Heedly is built for people whose profession runs on confidentiality. This page states, plainly, where your data lives, how it is protected, and what we will never do with it.
All application data — tasks, check-ins, career plans, reports — is stored with Supabase, our database and authentication provider, in the European Union. Every table is protected by per-user row-level security: each account can only ever read its own rows, enforced by the database itself, not just by the application. Supabase is SOC 2 Type II and ISO 27001 certified. The application is served by Vercel; our API runs as server-side functions there.
All traffic between your device and Heedly uses TLS 1.2 or higher. Data is encrypted at rest (AES-256) by our database provider. Calendar tokens — the most sensitive credentials we hold — are stored server-side only and are never sent to your browser.
AI features (the coach, reports, realism checks) call our own server, which relays the relevant text to OpenAI. The API key never runs in your browser. OpenAI does not use data submitted through its API to train models. A signed Data Processing Agreement with OpenAI is in place, and EU-to-US transfers are covered by Standard Contractual Clauses. No sensitive wellbeing data — sleep hours, stress scores, energy levels — is ever included in AI requests.
Heedly coaches you, not your case files. For lawyers, onboarding establishes the working rule: use matter codes, never client names. Heedly never needs to know who your client is to coach you — and every feature works fully without that information ever entering the system.
We do not sell data. We do not show ads. We do not use tracking pixels, advertising networks or social-media trackers. Inside the app there is no analytics at all; on the public website we use PostHog (EU cloud) for anonymous page statistics. Your data is not used to train AI models — not by us, and not by our providers.
You can delete your account, and everything in it, from inside the app — no email, no waiting period. Data export is available on request at info@heedly.app under Art. 20 GDPR.
The full, current list of subprocessors — Supabase, Vercel, OpenAI, Stripe, Apple, Resend, PostHog, and Google/Microsoft where you connect a calendar — is maintained in section 6 of our privacy policy, with the role of each.
Security or data-protection questions, or anything a procurement or compliance review needs: info@heedly.app. We answer these ourselves, not through a bot.